Before I start explaining why I'm here, I would like to tell whoever answers my post, that I have read the Self-help Malware Guide and followed the instructions on running the OTL Tool and it did not produce two Logs. It only gave me one Log that I have attached.
In the Self-help Guide, I read the "How to fix Googles Redirects Guide, I did not know that I was being redirected until I posted this problem over in the XP Forum and was told by tech "Happyrock" that I was being Redirected. So I have no Virus or Malware names to give you.
Okay, let me explain if I can.
For the last 4 days something strange has been going on with any Searches that I do, after click on Links.
I only use Yahoo as my search engine and had to do several searches on Yahoo over the last 4 days and when clicking on different Links, what happens is, instead of the Links taking me to that particular website, it just starts to download, that's it, no more information I can give about that.
Because my primary browser is Google Chrome, it opens up another window to start any downloads, which is what it did. After looking at these downloads, they looked weird, like they were encrypted.
I use the Free AVAST as my AntiVirus Program. There is a tool which is part of AVAST that I have never seen before that pops up on the screen that's called Sandbox, it's been popping up oh say a little over a month.
To say the least, it's very annoying because, this Sandbox Tool and this Infection Blocker Box pops up with things that I've used since I've had this PC that have never caused any Malware problems or Virus's for that matter, they even pop up when I go to check my E-mail on Yahoo, which I've done forever and I believe is total nonsense.
A little over a year ago, one of the Techs told me to start using the AFT Cleaner and TFC Tools that I use almost everyday to clean out my files and folders, and every time I use both, the Sandbox opens up. So after looking more closely at this Tool, I saw that I could tell it that it's okay to use these two Tools ("AFT and TFC") as much as I want without the Sandbox thinking that it was unsafe.
With that said, some how, I honestly believe that this Sandbox may be the cause of putting Malware and/or any Virus that maybe found on my system. Every thing was going pretty good until this thing appeared. Why and where this Tool came from, I have NO idea. Because I have had AVAST on my PC since the beginning of 2010, AVAST never gave me any idea that this Tool was being downloaded onto my system, so I have no other reason but to believe that this Tool is causing my problems now.
I opened up AVAST and read to see if there was a way I could disconnect it, but there is none.
I'm running WinXP and have a DELL 3000
I hope I was clear enough.
Thank U for any help you can give.
OTL logfile created on: 4/26/2011 9:20:57 PM - Run 2
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Debra Flowers\My Documents\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1,022.00 Mb Total Physical Memory | 453.00 Mb Available Physical Memory | 44.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 86.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 71.62 Gb Total Space | 54.61 Gb Free Space | 76.26% Space Free | Partition Type: NTFS
Computer Name: DEBRA | User Name: Debra Flowers | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Debra Flowers\My Documents\DOWNLOADS\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft Limited)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft Limited)
PRC - C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\Debra Flowers\My Documents\DOWNLOADS\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\AVAST Software\Avast\snxhk.dll (AVAST Software)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (mcupdmgr.exe) -- File not found
SRV - (HidServ) -- File not found
SRV - (Lavasoft Ad-Aware Service) -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft Limited)
SRV - (avast! Antivirus) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
SRV - (YahooAUService) -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
========== Driver Services (SafeList) ==========
DRV - (aswSnx) -- C:\WINDOWS\System32\drivers\aswSnx.sys (AVAST Software)
DRV - (aswSP) -- C:\WINDOWS\System32\drivers\aswSP.sys (AVAST Software)
DRV - (aswTdi) -- C:\WINDOWS\System32\drivers\aswTdi.sys (AVAST Software)
DRV - (aswMon2) -- C:\WINDOWS\System32\drivers\aswmon2.sys (AVAST Software)
DRV - (aswRdr) -- C:\WINDOWS\System32\drivers\aswRdr.sys (AVAST Software)
DRV - (Aavmker4) -- C:\WINDOWS\System32\drivers\aavmker4.sys (AVAST Software)
DRV - (aswFsBlk) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys (AVAST Software)
DRV - (Lavasoft Kernexplorer) -- C:\Program Files\Lavasoft\Ad-Aware\kernexplorer.sys ()
DRV - (Lbd) -- C:\WINDOWS\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (senfilt) -- C:\WINDOWS\system32\drivers\senfilt.sys (Creative Technology Ltd.)
DRV - (IntelC53) -- C:\WINDOWS\system32\drivers\IntelC53.sys (Intel Corporation)
DRV - (IntelC52) -- C:\WINDOWS\system32\drivers\IntelC52.sys (Intel Corporation)
DRV - (IntelC51) -- C:\WINDOWS\system32\drivers\IntelC51.sys (Intel Corporation)
DRV - (mohfilt) -- C:\WINDOWS\system32\drivers\mohfilt.sys (Intel Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.msn.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://zone.msn.com/en-us/home
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
O1 HOSTS File: ([2004/08/04 03:00:00 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll ()
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll ()
O3 - HKLM\..\Toolbar: (no name) - {98889811-442D-49dd-99D7-DC866BE87DBC} - No CLSID value found.
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: DriveConfiguration = [Binary data over 100 bytes]
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LegacyDrive = [Binary data over 100 bytes]
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} http://pccheckup.del...oad/tgctlcm.cab (Support.com Configuration Class)
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} file:///C:/Program%20Files/Magic%20Inlay/Images/stg_drm.ocx (SpinTop DRM Control)
O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.mi...b?1278719484687 (MUWebControl Class)
O16 - DPF: {80B626D6-BC34-4BCF-B5A1-7149E4FD9CFA} http://zone.msn.com/...O1.cab60096.cab (UnoCtrl Class)
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} http://www.worldwinn...ed/wwlaunch.cab (Wwlaunch Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {8C279F4E-917E-4CD2-8DF0-D9C73C0CE763} http://zone.msn.com/...of.cab55579.cab (ZPA_WheelOfFortune Object)
O16 - DPF: {8F6E7FB2-E56B-4F66-A4E1-9765D2565280} http://www.worldwinn....0/iewwload.cab (WorldWinner ActiveX Launcher Control)
O16 - DPF: {A4110378-789B-455F-AE86-3A1BFC402853} http://zone.msn.com/...vl.cab55579.cab (ZPA_SHVL Object)
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} http://cdn2.zone.msn...k.cab102118.cab (MSN Games - Installer)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macr...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E70E3E64-2793-4AEF-8CC8-F1606BE563B0} http://www.worldwinn...es/wwspades.cab (WWSpades Control)
O16 - DPF: {FF3C5A9F-5A99-4930-80E8-4709194C2AD3} http://zone.msn.com/...on.cab64162.cab (MSN Games – Backgammon)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Debra Flowers\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Debra Flowers\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/10 11:04:08 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/04/26 14:26:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Debra Flowers\Application Data\Sungift Games
[2011/04/26 14:26:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Sungift Games
[2011/04/24 12:25:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Debra Flowers\Application Data\Happy Muffin Top
[2011/04/23 13:35:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Debra Flowers\My Documents\Microsys
[2011/04/23 13:29:42 | 000,000,000 | ---D | C] -- C:\Program Files\Serious Backgammon
[2011/04/23 13:21:46 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/04/23 13:21:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/04/23 13:21:40 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2011/04/23 13:21:40 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2011/04/21 22:42:20 | 000,000,000 | ---D | C] -- C:\Program Files\RealArcade
[2011/04/21 11:07:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Debra Flowers\Application Data\Funlinker
[2011/04/18 20:58:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Debra Flowers\Application Data\My Games
[2011/04/15 09:31:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Debra Flowers\Local Settings\Application Data\WildWestStory
[2011/04/15 00:13:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Debra Flowers\Application Data\Cosmonaut Games
[2011/04/14 22:09:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Debra Flowers\Application Data\Zylom
[2011/04/14 22:09:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Zylom
[2011/04/14 21:46:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\n7-89-o9-3r-4t-r9
[2011/04/14 21:46:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Debra Flowers\Application Data\GameHouse
[2011/04/13 13:26:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Debra Flowers\Application Data\GestaltGames
[2011/04/13 13:26:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\GestaltGames
[2011/04/12 16:24:05 | 000,000,000 | ---D | C] -- C:\Program Files\bfgclient
[2011/04/12 15:46:58 | 000,019,544 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2011/04/12 15:46:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\avast! Free Antivirus
[2011/04/12 15:46:57 | 000,301,528 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSP.sys
[2011/04/12 15:46:55 | 000,049,240 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys
[2011/04/12 15:46:55 | 000,025,432 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys
[2011/04/12 15:46:54 | 000,371,544 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSnx.sys
[2011/04/12 15:46:54 | 000,102,232 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys
[2011/04/12 15:46:54 | 000,096,344 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon.sys
[2011/04/12 15:46:53 | 000,030,680 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys
[2011/04/12 15:46:33 | 000,040,648 | ---- | C] (AVAST Software) -- C:\WINDOWS\avastSS.scr
[2011/04/12 15:46:32 | 000,190,016 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\aswBoot.exe
[2011/04/12 15:46:20 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software
[2011/04/12 15:46:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\AVAST Software
[2011/04/11 11:10:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Debra Flowers\Application Data\Camel101
[2011/04/11 11:10:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Debra Flowers\Application Data\GarageGames
[2011/04/11 10:42:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Debra Flowers\Application Data\SpinTop Games
[2011/04/10 18:01:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Debra Flowers\Start Menu\Programs\Tower Software
[2011/04/08 10:31:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Debra Flowers\Application Data\Enki Games
[2011/04/06 11:24:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Debra Flowers\Application Data\TOMI3
[2011/04/04 16:16:47 | 000,000,000 | ---D | C] -- C:\ProgramData
[2011/04/02 14:35:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Debra Flowers\Application Data\Silverback Productions
[2011/04/02 11:41:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Debra Flowers\Application Data\MagicIndie
[2011/03/30 21:16:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Cateia Games
[2011/03/28 13:56:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Debra Flowers\Application Data\IBAGroup
[2011/03/28 13:20:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Debra Flowers\Application Data\HdO Adventure
========== Files - Modified Within 30 Days ==========
[2011/04/26 20:31:03 | 000,000,372 | ---- | M] () -- C:\Documents and Settings\Debra Flowers\My Documents\spider.sav
[2011/04/26 20:09:56 | 000,000,006 | ---- | M] () -- C:\WINDOWS\System32\x517_256.dll
[2011/04/26 08:38:13 | 000,000,486 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2011/04/26 08:36:39 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/04/26 08:36:32 | 1071,697,920 | -HS- | M] () -- C:\hiberfil.sys
[2011/04/26 01:53:40 | 000,000,064 | ---- | M] () -- C:\WINDOWS\System32\rp_stats.dat
[2011/04/26 01:53:40 | 000,000,044 | ---- | M] () -- C:\WINDOWS\System32\rp_rules.dat
[2011/04/24 11:45:23 | 000,001,194 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\More Great Games.lnk
[2011/04/23 13:35:04 | 000,000,128 | -H-- | M] () -- C:\Documents and Settings\Debra Flowers\microsoft.dat
[2011/04/23 13:29:43 | 000,001,626 | ---- | M] () -- C:\Documents and Settings\Debra Flowers\Desktop\Serious Backgammon.lnk
[2011/04/14 12:37:06 | 000,184,224 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011/04/12 15:46:58 | 000,001,689 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk
[2011/04/12 15:46:54 | 000,002,625 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2011/04/12 11:54:16 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2011/04/12 11:51:58 | 000,442,466 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2011/04/12 11:51:58 | 000,071,732 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
========== Files Created - No Company Name ==========
[2011/04/24 11:45:23 | 000,001,194 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\More Great Games.lnk
[2011/04/23 13:29:43 | 000,001,626 | ---- | C] () -- C:\Documents and Settings\Debra Flowers\Desktop\Serious Backgammon.lnk
[2011/04/12 16:24:16 | 000,001,584 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Game Manager.lnk
[2011/04/12 16:24:16 | 000,001,184 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\More Great Games.lnk
[2011/04/12 15:46:58 | 000,001,689 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk
[2011/04/08 17:24:32 | 000,001,077 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Default Manager.lnk
[2011/04/08 15:47:47 | 000,000,064 | ---- | C] () -- C:\WINDOWS\System32\rp_stats.dat
[2011/04/08 15:47:47 | 000,000,044 | ---- | C] () -- C:\WINDOWS\System32\rp_rules.dat
[2011/01/27 17:34:54 | 000,016,384 | ---- | C] () -- C:\WINDOWS\System32\msdrve.dll
[2011/01/27 17:34:53 | 000,010,816 | ---- | C] () -- C:\WINDOWS\vmoptver.dll
[2011/01/14 04:49:11 | 000,000,006 | ---- | C] () -- C:\WINDOWS\System32\b517_256.dll
[2010/12/28 09:17:00 | 000,061,678 | ---- | C] () -- C:\Documents and Settings\Debra Flowers\Application Data\PFP120JPR.{PB
[2010/12/28 09:17:00 | 000,012,358 | ---- | C] () -- C:\Documents and Settings\Debra Flowers\Application Data\PFP120JCM.{PB
[2010/12/28 09:14:06 | 000,001,682 | -HS- | C] () -- C:\WINDOWS\System32\KGyGaAvL.sys
[2010/12/28 09:14:06 | 000,000,056 | RHS- | C] () -- C:\WINDOWS\System32\0AEF98A4FB.sys
[2010/12/12 12:56:01 | 000,030,976 | ---- | C] () -- C:\WINDOWS\rascntrl.dll
[2010/12/12 12:56:01 | 000,023,104 | ---- | C] () -- C:\WINDOWS\System32\svcprmpt.dll
[2010/12/09 12:44:09 | 000,004,096 | ---- | C] () -- C:\WINDOWS\d3dx.dat
[2010/07/28 12:07:36 | 000,000,052 | ---- | C] () -- C:\WINDOWS\mafosav.INI
[2010/07/23 22:49:48 | 000,000,064 | ---- | C] () -- C:\WINDOWS\GPlrLanc.dat
[2010/07/21 14:01:16 | 000,004,994 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\gzzcrqnc.wrg
[2010/07/17 00:43:06 | 000,000,016 | ---- | C] () -- C:\WINDOWS\System32\syspvm-14.dll
[2010/06/14 21:10:14 | 000,004,608 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\os331msd.obj
[2010/06/11 09:25:54 | 000,000,000 | ---- | C] () -- C:\WINDOWS\hpqEmlSz.INI
[2010/06/06 12:43:00 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2010/06/05 20:48:35 | 000,000,006 | ---- | C] () -- C:\WINDOWS\System32\x517_256.dll
[2010/06/05 19:48:22 | 000,000,227 | ---- | C] () -- C:\WINDOWS\HP_CounterReport_Update_HPSU.ini
[2010/06/05 19:48:06 | 000,000,214 | ---- | C] () -- C:\WINDOWS\HP_48BitScanUpdatePatch.ini
[2010/06/05 19:45:32 | 000,000,221 | ---- | C] () -- C:\WINDOWS\HP_RedboxHprblog_HPSU.ini
[2010/06/05 19:29:26 | 000,112,924 | ---- | C] () -- C:\WINDOWS\hpoins07.dat
[2010/06/05 19:29:26 | 000,021,124 | ---- | C] () -- C:\WINDOWS\hpomdl07.dat
[2010/06/05 16:50:39 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2010/06/05 00:09:14 | 000,000,748 | ---- | C] () -- C:\Documents and Settings\Debra Flowers\Application Data\AtomicAlarmClock.ini
[2010/06/04 22:09:11 | 000,000,002 | ---- | C] () -- C:\WINDOWS\msoffice.ini
[2005/07/11 19:37:20 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2005/07/11 19:31:40 | 000,000,138 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2005/07/11 19:30:06 | 000,000,335 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2005/07/11 19:08:22 | 000,049,152 | ---- | C] () -- C:\WINDOWS\setpwrcg.exe
[2005/07/11 19:08:14 | 000,012,288 | ---- | C] () -- C:\WINDOWS\System32\e100bmsg.dll
[2005/07/11 19:07:56 | 000,000,375 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2004/08/10 11:12:05 | 000,000,780 | ---- | C] () -- C:\WINDOWS\orun32.ini
[2004/08/10 11:07:31 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2004/08/10 11:02:15 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2004/08/10 11:01:18 | 000,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2004/08/10 10:57:52 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2004/08/10 10:57:15 | 000,184,224 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2004/08/10 10:51:21 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2004/08/10 10:51:20 | 000,442,466 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2004/08/10 10:51:20 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2004/08/10 10:51:20 | 000,071,732 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2004/08/10 10:51:20 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2004/08/10 10:51:18 | 000,004,627 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2004/08/10 10:51:17 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2004/08/10 10:51:16 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2004/08/10 10:51:12 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2004/08/10 10:51:11 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2004/08/10 10:51:05 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2004/08/10 10:50:56 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin
[2001/07/06 15:30:00 | 000,003,399 | ---- | C] () -- C:\WINDOWS\System32\hptcpmon.ini
========== LOP Check ==========
[2010/12/03 00:23:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Alawar Stargaze
[2010/10/04 18:14:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AlawarWrapper
[2010/07/05 08:25:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Alwil Software
[2011/04/12 15:46:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVAST Software
[2011/04/12 16:24:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Big Fish Games
[2010/12/24 14:04:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Casual Arts
[2011/03/31 08:12:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Cateia Games
[2011/03/11 15:25:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Elephant Games
[2010/07/26 00:24:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ERS G-Studio
[2011/04/12 21:32:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Far Mills
[2010/12/08 21:51:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FLARUFQAYG
[2010/12/25 17:57:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Flood Light Games
[2010/11/30 17:11:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Floodlight Games
[2010/07/23 22:58:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Free Ride Games
[2011/02/06 16:50:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Fugazo
[2010/06/22 21:28:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Game Club Cafe Game Downloads
[2010/08/11 16:54:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Gamers Digital
[2010/08/11 15:07:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\GamersDigital
[2011/04/13 13:26:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\GestaltGames
[2010/12/08 17:37:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Gogii
[2011/01/26 00:32:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Gold Casual Games
[2010/11/29 23:03:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\HitPoint Studios
[2010/06/15 17:13:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\hitpointstudios
[2010/07/19 20:04:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Intenium
[2011/01/21 15:04:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\JollyBear
[2010/12/08 22:14:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\JRARUFQAYG
[2011/03/09 16:13:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Kristanix Games
[2010/12/08 22:30:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\LAARUFQAYG
[2010/12/20 05:17:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\LittleGamesCompany
[2010/12/08 22:45:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\LPARUFQAYG
[2010/07/18 19:15:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Merscom
[2010/06/09 20:54:32 | 000,000,000 | -HSD | M] -- C:\Documents and Settings\All Users\Application Data\mgp_data
[2011/02/18 19:14:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MumboJumbo
[2011/02/09 22:22:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MysteryChronicles
[2011/04/14 21:46:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\n7-89-o9-3r-4t-r9
[2011/01/22 13:09:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Namco
[2010/07/19 14:27:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NeoEdge Networks
[2010/07/29 23:16:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Particles
[2010/12/10 19:12:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PLARUFQAYG
[2011/04/24 11:47:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PlayFirst
[2011/03/21 22:42:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PlayPond
[2011/02/17 21:46:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Playrix Entertainment
[2011/02/15 16:59:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PuzzlesByJoe
[2011/03/01 16:45:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Sandlot Games
[2010/07/19 20:04:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ScreenSeven
[2010/12/30 14:20:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SpecialBit
[2011/03/17 00:16:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SulusGames
[2011/04/26 02:17:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2010/07/09 16:47:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\The Inquisitor
[2011/03/01 16:04:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TikisLab
[2011/04/23 11:16:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Top Evidence
[2010/12/08 23:30:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ULARUFQAYG
[2011/03/23 10:37:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Venus DS
[2005/07/11 19:31:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
[2010/12/08 21:50:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\VKARUFQAYG
[2011/01/11 20:27:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WorldWinner
[2010/12/08 21:52:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\XDARUFQAYG
[2011/04/14 22:09:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Zylom
[2010/07/23 20:40:02 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\{BD986C1B-72EC-4B82-B47B-6CAC4E6F494E}
[2011/01/09 21:08:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\2monkeys
[2011/03/10 18:22:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\Aerohills
[2011/03/14 20:43:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\Alawar
[2010/12/24 21:22:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\Artifex Mundi
[2011/03/25 13:23:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\Artogon
[2010/06/07 19:23:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\Auslogics
[2010/07/17 12:38:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\Awem
[2010/12/21 15:51:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\AweSEM
[2010/07/28 01:29:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\Azuaz Games
[2011/01/29 01:08:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\Big Fish Games
[2011/03/26 16:55:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\Blue Tea Games
[2011/04/19 21:43:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\Boomzap
[2011/04/11 12:42:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\Camel101
[2010/12/24 14:04:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\Casual Arts
[2010/08/21 14:15:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\Cat's Eye Games
[2010/12/19 21:58:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\cerasus.media
[2011/02/02 23:43:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\ChaYoWo Games
[2011/04/15 00:13:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\Cosmonaut Games
[2011/03/12 15:02:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\CursedOnboard
[2010/07/29 21:51:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\DigirononGames
[2011/01/23 17:20:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\EleFun Games
[2011/03/11 15:25:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\Elephant Games
[2011/04/08 15:40:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\Enki Games
[2010/07/25 23:06:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\ERS G-Studio
[2011/04/22 23:12:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\ERS Game Studios
[2010/12/25 17:57:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\Flood Light Games
[2010/11/30 17:11:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\Floodlight Games
[2011/01/18 20:42:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\FlyWheelGames
[2010/07/11 15:44:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\FreezeTag
[2011/03/13 17:09:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\Friday's games
[2010/11/29 14:53:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\Frogwares
[2010/12/07 18:02:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\Fugazo
[2011/04/21 11:07:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\Funlinker
[2011/02/23 15:11:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\Fuzzy Bug Interactive
[2011/04/14 21:46:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\GameHouse
[2011/01/20 02:12:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\GameInvest
[2011/04/11 20:40:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\GameMill Entertainment
[2010/08/11 16:54:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\Gamers Digital
[2010/08/11 15:07:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\GamersDigital
[2011/03/02 20:54:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\GAMGO
[2011/04/11 11:10:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\GarageGames
[2010/07/12 15:09:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\Gestalt Games
[2011/04/13 13:26:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\GestaltGames
[2011/01/18 00:11:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\Ghost Ship Studios
[2010/12/08 17:37:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\gogii
[2011/01/26 00:32:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\Gold Casual Games
[2011/02/28 16:20:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\GTM_Bodie
[2011/04/24 13:33:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\Happy Muffin Top
[2011/04/12 17:58:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\HdO Adventure
[2011/03/26 21:24:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\HillStoneAnimationStudios
[2010/12/14 18:59:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\HiT-MM
[2011/03/31 22:56:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\HitPoint Studios
[2011/04/13 10:53:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\IBAGroup
[2010/12/13 07:47:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\Image Zone Express
[2011/01/21 19:13:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\iWin
[2010/12/04 14:12:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\JoyBits
[2010/08/20 21:52:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\Lazy Turtle Games
[2010/12/20 05:17:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\LittleGamesCompany
[2011/01/29 19:30:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\MA2
[2011/04/02 12:59:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\MagicIndie
[2011/03/04 13:34:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\margrave3_full
[2010/06/30 11:12:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\Mariaglorum
[2010/12/23 19:07:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\Meridian93
[2010/07/18 19:15:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\Merscom
[2010/07/06 23:02:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\Mutant Arcade
[2011/04/18 20:58:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\My Games
[2010/08/20 23:09:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\MysteriousCaseOfJekyllAndHyde
[2011/04/05 09:55:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\Namco
[2011/04/24 23:42:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\Oberon Media
[2011/04/12 19:05:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\Odian Games
[2011/01/24 10:34:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\Old Castle
[2011/04/26 02:23:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\Orneon
[2011/04/24 11:47:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\PlayFirst
[2010/12/27 02:38:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\PlayPond
[2011/01/21 16:19:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\Pogo Games
[2011/01/15 17:00:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\PriceGong
[2011/03/04 16:15:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\QB9
[2010/06/20 19:11:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\Scholastic
[2010/07/19 17:21:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\ScreenSeven
[2011/03/09 17:23:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\SevenSails
[2010/12/04 02:47:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\ShinyTales
[2011/04/02 19:14:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\Silverback Productions
[2010/06/11 22:16:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\Skunk Studios
[2010/12/30 14:20:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\Specialbit
[2010/12/01 17:05:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\SpinTop
[2011/04/23 19:11:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\SpinTop Games
[2011/03/17 00:16:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\SulusGames
[2010/07/09 16:47:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\The Inquisitor
[2011/02/28 13:36:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\TikisLab
[2011/04/06 11:25:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\TOMI3
[2011/04/23 11:16:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\Top Evidence
[2010/11/29 19:58:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\Total Eclipse
[2011/02/22 21:46:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\TreeCardGames
[2010/12/08 19:07:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\Vast Studios
[2011/03/20 14:50:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\Vogat Interactive
[2011/01/27 13:36:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\WhiteBirdsProductions
[2011/04/14 22:09:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Debra Flowers\Application Data\Zylom
[2011/04/26 08:38:13 | 000,000,486 | ---- | M] () -- C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 97 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:E690114B
@Alternate Data Stream - 235 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:AECF4772
@Alternate Data Stream - 235 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0EC7A545
@Alternate Data Stream - 231 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:BF6A2C54
@Alternate Data Stream - 230 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:B54E4B5A
@Alternate Data Stream - 228 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:B6E6C4EA
@Alternate Data Stream - 217 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:834DD57E
@Alternate Data Stream - 208 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:116F958F
@Alternate Data Stream - 198 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:AABCC5A7
@Alternate Data Stream - 188 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:9A69BCBB
@Alternate Data Stream - 182 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:18997511
@Alternate Data Stream - 167 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:B812F293
@Alternate Data Stream - 150 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:58F78E08
@Alternate Data Stream - 149 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:E189EC1B
@Alternate Data Stream - 149 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:52FE3CCD
@Alternate Data Stream - 149 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:20BC9A76
@Alternate Data Stream - 149 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:14A1BBE3
@Alternate Data Stream - 148 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:BF6C81B2
@Alternate Data Stream - 148 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:938EB9FC
@Alternate Data Stream - 147 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:F5B51004
@Alternate Data Stream - 147 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A819A132
@Alternate Data Stream - 147 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:9BDF1A6A
@Alternate Data Stream - 146 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C356A185
@Alternate Data Stream - 145 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:E8C44CB4
@Alternate Data Stream - 145 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:AF5DCAD7
@Alternate Data Stream - 145 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:AD020DC3
@Alternate Data Stream - 145 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A9E8066F
@Alternate Data Stream - 145 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:8F925134
@Alternate Data Stream - 145 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:3969ACF7
@Alternate Data Stream - 145 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:1AAEFD5D
@Alternate Data Stream - 145 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0785072C
@Alternate Data Stream - 144 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C9665738
@Alternate Data Stream - 144 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:90FE524C
@Alternate Data Stream - 144 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:8E5EA40F
@Alternate Data Stream - 144 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:6B804134
@Alternate Data Stream - 143 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D72D7897
@Alternate Data Stream - 143 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:CFA8C6E3
@Alternate Data Stream - 143 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:B8EB1B99
@Alternate Data Stream - 143 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:79875988
@Alternate Data Stream - 143 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5CE91C67
@Alternate Data Stream - 143 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:397D67BA
@Alternate Data Stream - 143 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:1D6B18F1
@Alternate Data Stream - 142 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:E6BEADB7
@Alternate Data Stream - 142 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:99B20AD0
@Alternate Data Stream - 142 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:956EC010
@Alternate Data Stream - 142 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:8BE8BFCD
@Alternate Data Stream - 142 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:8924043A
@Alternate Data Stream - 142 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:71B89F61
@Alternate Data Stream - 142 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:4C8FA829
@Alternate Data Stream - 142 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:19474103
@Alternate Data Stream - 141 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:91A12471
@Alternate Data Stream - 141 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:7C0CBD4C
@Alternate Data Stream - 141 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5782349A
@Alternate Data Stream - 141 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:54380FEC
@Alternate Data Stream - 141 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:3867977D
@Alternate Data Stream - 140 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:8B4B9596
@Alternate Data Stream - 140 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:3FC46878
@Alternate Data Stream - 140 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:30E0D641
@Alternate Data Stream - 140 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:021496FB
@Alternate Data Stream - 139 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:E6C6EB3B
@Alternate Data Stream - 139 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C8F88A8F
@Alternate Data Stream - 139 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A0921B2C
@Alternate Data Stream - 139 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:02E56DC6
@Alternate Data Stream - 138 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:EBCF5924
@Alternate Data Stream - 138 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:E5B07840
@Alternate Data Stream - 138 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DDF112BD
@Alternate Data Stream - 138 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C2E76130
@Alternate Data Stream - 137 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DB4C77AD
@Alternate Data Stream - 137 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C49A5AD1
@Alternate Data Stream - 137 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:94B46CA2
@Alternate Data Stream - 137 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:3086B95F
@Alternate Data Stream - 137 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:25249477
@Alternate Data Stream - 137 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0BBF232A
@Alternate Data Stream - 137 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:05670151
@Alternate Data Stream - 136 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:EAF954B6
@Alternate Data Stream - 136 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:EA1919C7
@Alternate Data Stream - 136 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:35CF1C69
@Alternate Data Stream - 136 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:190B5C6B
@Alternate Data Stream - 135 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:F6FE6031
@Alternate Data Stream - 135 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:9FD757A9
@Alternate Data Stream - 135 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5FD26EF3
@Alternate Data Stream - 135 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0F38B460
@Alternate Data Stream - 134 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C2F24DB5
@Alternate Data Stream - 134 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:B0456F0C
@Alternate Data Stream - 134 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:AA0017FD
@Alternate Data Stream - 134 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:8FCCCD6D
@Alternate Data Stream - 134 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:7C8AA9A6
@Alternate Data Stream - 134 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:737160C1
@Alternate Data Stream - 134 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:70DFEEF4
@Alternate Data Stream - 134 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5A6115DD
@Alternate Data Stream - 134 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:207C4C79
@Alternate Data Stream - 133 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D9656460
@Alternate Data Stream - 133 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:CAE3AE67
@Alternate Data Stream - 133 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:BD34FFC5
@Alternate Data Stream - 133 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:B190BE3A
@Alternate Data Stream - 133 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A445F715
@Alternate Data Stream - 133 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:852F2262
@Alternate Data Stream - 133 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:80EA2EA3
@Alternate Data Stream - 133 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:7FFBA7B1
@Alternate Data Stream - 133 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:6F16D671
@Alternate Data Stream - 133 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:34445512
@Alternate Data Stream - 132 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:F84B8DB5
@Alternate Data Stream - 132 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A9C7B545
@Alternate Data Stream - 132 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:7ADB695A
@Alternate Data Stream - 132 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:33B04540
@Alternate Data Stream - 132 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:09C298DD
@Alternate Data Stream - 131 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:BE6B5FC3
@Alternate Data Stream - 131 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A5241382
@Alternate Data Stream - 131 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5080697C
@Alternate Data Stream - 131 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:23834E1E
@Alternate Data Stream - 131 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:204BEE0F
@Alternate Data Stream - 130 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:F663BB74
@Alternate Data Stream - 130 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:EAD4A155
@Alternate Data Stream - 130 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:E463CA56
@Alternate Data Stream - 130 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:9C504A4D
@Alternate Data Stream - 130 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:864881BF
@Alternate Data Stream - 130 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:75798D9A
@Alternate Data Stream - 130 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:65B701A9
@Alternate Data Stream - 130 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:52C24010
@Alternate Data Stream - 130 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:31996194
@Alternate Data Stream - 129 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:B3196E8D
@Alternate Data Stream - 128 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:CDF47D67
@Alternate Data Stream - 128 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A5584049
@Alternate Data Stream - 128 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:4B87381C
@Alternate Data Stream - 128 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:4B1AE40C
@Alternate Data Stream - 128 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0E8117B1
@Alternate Data Stream - 127 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:CF5ECDE7
@Alternate Data Stream - 127 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:B38BEEEE
@Alternate Data Stream - 127 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:87E0E06D
@Alternate Data Stream - 127 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:6F0B6A5A
@Alternate Data Stream - 127 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:59465B40
@Alternate Data Stream - 127 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:3AAFEFCD
@Alternate Data Stream - 127 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:2B856118
@Alternate Data Stream - 127 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:1C201DEB
@Alternate Data Stream - 126 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:E2CFA9CD
@Alternate Data Stream - 126 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D3A82449
@Alternate Data Stream - 126 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:CA23BCFD
@Alternate Data Stream - 126 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C0893153
@Alternate Data Stream - 126 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:961B84C5
@Alternate Data Stream - 126 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:268BA8AB
@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:EF38B79C
@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:B2CD146E
@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:31346E1D
@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:1170D6E4
@Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:B8AE59B8
@Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A6D6E537
@Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A4E7D25F
@Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5D9A374E
@Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:16EEDD02
@Alternate Data Stream - 123 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:BE40C8A2
@Alternate Data Stream - 123 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:902B6A44
@Alternate Data Stream - 123 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:53B8C5D2
@Alternate Data Stream - 123 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:4FA837B4
@Alternate Data Stream - 123 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:3E200C29
@Alternate Data Stream - 123 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:1B389835
@Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C0A504B9
@Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:4A077D87
@Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:34EFF1F2
@Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:2AF322BF
@Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:29861223
@Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:80F61F6F
@Alternate Data Stream - 120 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:4E9035C9
@Alternate Data Stream - 120 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:2DF54B62
@Alternate Data Stream - 119 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D6D084A5
@Alternate Data Stream - 119 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D48500F8
@Alternate Data Stream - 119 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A6D89509
@Alternate Data Stream - 119 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:90180C1D
@Alternate Data Stream - 119 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:86B7FDDB
@Alternate Data Stream - 119 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:73AFBB96
@Alternate Data Stream - 119 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:65B8AF94
@Alternate Data Stream - 119 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:63C29481
@Alternate Data Stream - 119 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:512E1728
@Alternate Data Stream - 119 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:3AD6342E
@Alternate Data Stream - 119 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:1EEB23AD
@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DB2748F7
@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:BCDBBA6D
@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:8BE7A048
@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:774A0E14
@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:689AB7E9
@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:3AE50743
@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:3539CD43
@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:20767002
@Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:2C22C34B
@Alternate Data Stream - 114 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:378824DE
@Alternate Data Stream - 113 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:CCB49694
@Alternate Data Stream - 113 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:AFB24B00
@Alternate Data Stream - 113 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:4DDE401B
@Alternate Data Stream - 112 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:ACECBBFF
@Alternate Data Stream - 112 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:71A89A93
@Alternate Data Stream - 112 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:71112705
@Alternate Data Stream - 111 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C63E7DE2
@Alternate Data Stream - 111 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:7881FECE
@Alternate Data Stream - 111 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:1B0EE21A
@Alternate Data Stream - 110 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:551BED5F
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:F43628AB
@Alternate Data Stream - 108 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:2C460E20
@Alternate Data Stream - 107 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:561B1D2B
@Alternate Data Stream - 106 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:4911BB5C
@Alternate Data Stream - 105 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C22674B6
< End of report >
Edited by simplee55, 27 April 2011 - 12:14 AM.